ClawTrust LogoClawTrust
Supabase

Supabase

by lucassynnott · v1.0.0

Data Analysis
ClawHub
7.6
/ 10
1 evaluations
5.3k Downloads

Overview

Provide an agent-accessible CLI wrapper around Supabase (Postgres + pgvector + storage/management) to run SQL queries, CRUD operations, RPC calls, and vector similarity search using environment-configured Supabase credentials.

Key Advantages

1.Comprehensive coverage of Supabase database features: raw SQL, CRUD, upsert, RPC, table listing, and schema inspection.
2.Built-in vector similarity search via pgvector with support for custom match functions and configurable limits/thresholds.
3.Straightforward environment-based configuration (SUPABASE_URL, SUPABASE_SERVICE_KEY, optional anon/access tokens, OPENAI_API_KEY).
4.Clear, concrete command patterns with many examples, making it easier for agents to synthesize correct calls (query, select filters, insert, update, delete, upsert, rpc).
5.Supports performance-oriented vector search setups (ivfflat index, cosine ops) when the database is configured accordingly.

Use Cases

  • Agent-driven analytics and reporting on Supabase-backed applications via SQL and filtered selects.
  • CRUD and upsert operations for internal tools (e.g., managing users, posts, products, sessions).
  • Implementing an LLM-powered knowledge base or RAG system backed by Supabase + pgvector for document embeddings and similarity search.
  • Maintenance and operational tasks such as cleaning up old sessions, updating flags, or running scheduled SQL updates through an agent.
  • Schema exploration and debugging via listing tables and describing table structures from within an AI workflow.

Evaluation Scores

7.6
/ 10
Reliability
7.4
Functionality
8.8
Usability
8.1
Safety
5.8
Performance
8.0
Compatibility
7.8

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

7.6/103/19/2026
▼
OS: linux-arm64LLM: google/gemini-3-flash-preview
**Judgement:** This is a powerful, general-purpose Supabase integration that exposes most of what you can do with Supabase/Postgres (including pgvector) to an agent. It is well-documented and flexible, but comes with **significant safety and data-integrity risks** if given broad access to a production database. **What it does well** - Covers a wide range of operations: raw SQL (`query`), filtered `select`, `insert`/`update`/`upsert`/`delete`, `rpc` for stored procedures, table listing, schema inspection, and `vector-search` using pgvector. - Clearly defined CLI interface with many examples, which is friendly for LLM planning and reduces ambiguity in how to form commands. - Supports vector search with configurable thresholds and limits, and recommends proper pgvector setup (extension, index, similarity function), enabling performant semantic search use cases. **Key risks and limitations** - **Service role key risk:** The recommended `SUPABASE_SERVICE_KEY` has full access and bypasses row-level security. In the hands of an agent, this allows: - Unbounded `DELETE` or destructive `UPDATE` statements. - Arbitrary `query` commands, including `DROP TABLE`, schema changes, or mass data modifications. - **Lack of guardrails:** The skill exposes raw SQL and broad CRUD with no built-in protections such as: - Read-only mode, whitelisting of tables, or query allowlists. - Confirmation steps for destructive commands. - **Injection / prompt-risk surface:** Because the agent composes SQL and filters from natural language, malicious or unintentionally dangerous instructions can directly translate into harmful database operations. - **Operational fragility:** Correct behavior depends on external configuration (Supabase project, pgvector extension, indexes, environment variables, OpenAI API key for embeddings). Misconfiguration will lead to failures that the skill itself does not mitigate. **Recommended scenarios** Use this skill **where high capability is more important than strict safety**, and where you can constrain the environment: - **Staging / development databases** where data loss is acceptable and you want rapid iteration on: - Analytics and reporting via SQL. - Prototyping agent-based backends and CRUD flows. - Experimenting with Supabase + pgvector RAG setups. - **Internal tools and ops agents** with: - Carefully scoped schemas (e.g., a separate DB or schema for the agent). - Preferably restricted keys (anon or custom policies) when possible instead of the full service role key. For **production or sensitive data**, this skill should only be used with: - Strong external safeguards (read-only roles, separate databases/schemas, or middleware that filters SQL). - Clear, enforced policies on which operations the agent is allowed to perform (e.g., analytics only, no `delete`/`update`/raw `query` on critical tables). In short, this skill is **highly capable but low-guardrail**. It is best suited to controlled environments, staging systems, and well-scoped internal automations rather than direct, unconstrained access to critical production databases.

Comments (0)

Post a Comment

No comments yet. Be the first!